|
Message-ID: <Xls8qrS5_QdyztMHIXiGOs26w4bnyy7HCqgLUBG9FIGCNqQyMeybftwXamy4KzE_p9kQzxbAtQ7A5PAmRZKAY9S90mHAK5YC9vjHQcxqqgY=@protonmail.com> Date: Sat, 08 Jul 2023 21:08:38 +0000 From: Barnabás Pőcze <pobrn@...tonmail.com> To: Tavis Ormandy <taviso@...il.com> Cc: oss-security@...ts.openwall.com Subject: Re: manjaro pamac vulnerability Hi 2023. július 7., péntek 06:44 keltezéssel, Tavis Ormandy <taviso@...il.com> írta: > FYI, I noticed a blog post about this: > > https://github.com/c-skills/vala-vala-hey/blob/master/vala-vala-hey > > I didn't test it, but if you can't trust stealth who can you trust? :) > > I'm not familiar with manjaro, I dunno if it's the polkit config for their dbus service. > [...] It looks like it has been fixed: https://gitlab.manjaro.org/applications/libpamac/-/commit/889aa1d74ad305bb28178396dcc16e5b5381ade6 Regards, Barnabás Pőcze
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.